Vulnerability CVE-2019-11041: Information

Description

When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.1.x below 7.1.31, 7.2.x below 7.2.21 and 7.3.x below 7.3.8 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.

Severity: HIGH (7.1) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

Published: Aug. 9, 2019
Modified: Feb. 28, 2023
Error type identifier: CWE-125

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      7.1.0
      End excliding
      7.1.31

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      7.2.0
      End excliding
      7.2.21

      cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
      Start including
      7.3.0
      End excliding
      7.3.8

      Configuration 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

      Configuration 4

      cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
      End excliding
      10.15.1

      Configuration 5

      cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

      Configuration 6

      cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*

      Configuration 7

      cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:*
      End excliding
      5.19.0